Browser Lite
by Yandex
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-26226 | Cri | 0.64 | 9.8 | 0.00 | May 30, 2025 | A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682 | ||
| CVE-2024-6473 | Hig | 0.51 | 7.8 | 0.01 | Sep 3, 2024 | Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used. | ||
| CVE-2021-25263 | Hig | 0.51 | 7.8 | 0.00 | Aug 17, 2021 | Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process. | ||
| CVE-2021-25255 | Hig | 0.49 | 7.5 | 0.01 | May 21, 2025 | Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service. | ||
| CVE-2016-8508 | Med | 0.42 | 6.5 | 0.02 | Mar 1, 2017 | Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site. | ||
| CVE-2021-25262 | Med | 0.35 | 5.4 | 0.00 | May 21, 2025 | Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack. | ||
| CVE-2021-25254 | Med | 0.34 | 5.3 | 0.01 | May 21, 2025 | Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar. |
- risk 0.64cvss 9.8epss 0.00
A use after free memory corruption issue exists in Yandex Browser for Desktop prior to version 24.4.0.682
- risk 0.51cvss 7.8epss 0.01
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
- risk 0.51cvss 7.8epss 0.00
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Browser update process.
- risk 0.49cvss 7.5epss 0.01
Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.
- risk 0.42cvss 6.5epss 0.02
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
- risk 0.35cvss 5.4epss 0.00
Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.
- risk 0.34cvss 5.3epss 0.01
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.